Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Also called Policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Exclusions in context, with comparison tables and the common traps.
Terms in this definition
- Policy assignment
What makes a policy definition or initiative take effect: it targets a management group, subscription or resource group, supplies parameter values, exclusions, an enforcement mode and non-compliance messages, and starts a compliance scan.
Related terms
- AAD DC Administrators
Grants members admin rights over joined VMs and control of Group Policy for AADDC containers in an Entra Domain Services managed domain. Enterprise Admins and Domain Admins rights don't exist there.
- ABAC policy
Governed tags drive this kind of Unity Catalog rule: when a table or column has tags that satisfy its
WHENandMATCH COLUMNSconditions, a row filter or column mask UDF is put on it automatically. Policies are written withCREATE POLICYand can sit on a metastore, catalog, schema or table. - Activity log
Record, held for 90 days, of control-plane operations in a subscription such as deployments and Policy events. Data-plane actions, Key Vault reads for example, are not captured.
- AD LDS
Directory service role offering applications an LDAP store on its own, with no Group Policy or domains.
- Administrative Templates
ADMX-based Group Policy settings. Intune lists the built-in ones among the settings catalog's entries; ADMX files that you bring yourself show up as Imported Administrative templates.
- ADMX
Group Policy settings are defined in these XML files. The settings catalog in Intune already has many settings that depend on them, and you may import up to 20 of your own or third-party ones, at most 1 MB each and in en-us only, along with matching ADML files.
- Advanced Audit Policy Configuration
Holds fine-grained audit subcategories (Audit Credential Validation, for instance) in Group Policy, superseding the nine basic categories.
- Agent risk
Condition in Conditional Access based on the risk level Microsoft Entra ID Protection assigns to agent identities, letting a policy stop high-risk agents from obtaining tokens.